Skip to content

[NO-TICKET] Guide agents through guard wiring across JavaScript frameworks - #342

Merged
mariojgt merged 1 commit into
mainfrom
docs/framework-guard-guidance
Oct 1, 2026
Merged

mariojgt merged 1 commit into
mainfrom
docs/framework-guard-guidance

Conversation

@mariojgt

@mariojgt mariojgt commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What changed

Add a guard-wiring checklist and entry-point guidance for 30 JavaScript frameworks and UI libraries to the shipped AGENT-INSTALL.md. Coding agents can use it to finish a manual integration, review an automatic edit, and report precisely what remains unverified.

Why

A framework name does not establish the deployed request path. Server hooks vary by version and adapter, and source checks cannot prove that every page, API, action or separately deployed function reaches the guard.

Fix

  • Trace the deployed server entry and choose a compatible guard API before editing.
  • Preserve existing middleware and distinguish the Express guard's parsed-body ordering from the generic Node guard's raw-stream ordering.
  • Link official lifecycle references for 30 frameworks, including Next.js middleware/proxy conventions and Gatsby functions alongside static pages.
  • Give the coding agent a bounded handoff for unresolved wiring, with files, failing checks, remaining edits and coverage gaps.

Verified

  • npm run typecheck, npm run build, npm test: 239 test files passed; 4,084 tests passed and 7 skipped. Tests ran with local listeners permitted.
  • npm run capabilities:check: passed.
  • npm pack --dry-run --json: confirms the edited reference is included.
  • Ran the built CLI against 30 synthetic source fixtures and compared a second scaffold run: all 30 were byte-stable. Five source checks passed, 22 needed manual wiring, and three reported static/not applicable. These are CLI observations, not runtime compatibility results.
  • Reviewed the Next.js fixture's competing middleware/proxy files and Gatsby's static verdict with an included src/api function; the guidance calls for explicit entry and deployment review in both cases.

Out of scope

Automatic detection, adapter implementations and runtime behavior are unchanged. The 30 representative projects are synthetic source fixtures, not fully installed applications; their framework builds and runtime request coverage have not been tested. This change expands agent guidance, not the automatic compatibility claim.

The hostile field test remains outstanding until the release containing this reference, as required by MAINTAINING.md: that harness installs the published tarball and cannot validate these unpublished docs. Run node field-test/run.mjs --persona hostile --rounds 3 immediately after that release.

Docs: this change is limited to the shipped agent install reference. No install prompt or runtime code changes.

  • I reviewed the code, comments, fixtures, commit messages, generated output, and PR description for private Patchstack or customer information.
  • Nothing here is third-party confidential or proprietary material. The fixtures are synthetic and the framework references are public official documentation.

@coderbuds

coderbuds Bot commented Oct 1, 2026

Copy link
Copy Markdown

Comprehensive manual guard wiring guide added with clear framework-specific instructions.

🎯 Quality: 95% Elite · 📦 Size: Small

📈 This month: Your 165th PR — above team average · Averaging Excellent

See how your team is trending →

@mariojgt

mariojgt commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/review

@mariojgt
mariojgt merged commit 4f7c999 into main Oct 1, 2026
18 checks passed
@mariojgt
mariojgt deleted the docs/framework-guard-guidance branch October 1, 2026 10:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants